Proof, not promises. How Emberalis protects the most sensitive data you own.
Everything in your vault, from passwords to files to farewell messages, is encrypted in your browser before it ever reaches us. The keys are derived from your password on your device and never leave it. In plain terms: we cannot read your data, even if we wanted to, even if we were compelled to, even if our servers were breached.
Want the full technical design (key hierarchy, escrow model, algorithm choices)? Ask us and we will share the architecture documentation.
These are the vendors we rely on, what they do for us, and where your data is processed. Vault content reaches none of them in readable form.
| Vendor | Purpose | Data | Region | Transfer basis |
|---|---|---|---|---|
| Appwrite Cloud | Backend platform: database, authentication, file storage | Account data, encrypted vault items and files (zero-knowledge: content is encrypted client-side) | United States (NYC region) | EU Standard Contractual Clauses (SCCs) |
| Vercel | Application hosting, edge network and cron scheduling | Request metadata (IP addresses, logs) | Global edge, primary EU/US | EU-US Data Privacy Framework / SCCs |
| Stripe | Payments and subscription billing | Name, email, payment details, billing history | United States / European Union | EU-US Data Privacy Framework |
| Twilio | SMS and WhatsApp delivery (phone verification, check-ins) | Phone numbers, message delivery metadata | United States | EU-US Data Privacy Framework |
| Resend | Transactional email (verification, check-ins, emergency alerts) | Email addresses, email content and delivery metadata | United States | EU Standard Contractual Clauses (SCCs) |
| Loops | Marketing and lifecycle email | Email address, name, product usage milestones | United States | EU Standard Contractual Clauses (SCCs) |
| Sentry | Error tracking and cron monitoring | Error reports and diagnostics (PII scrubbed before sending) | United States | EU-US Data Privacy Framework |
| PostHog | Product analytics (event tracking only, no feature flags) | Pseudonymous usage events, device metadata | European Union (EU Cloud) | Processed within the EU |
| LaunchDarkly | Feature flags | User identifier for flag targeting | United States | EU-US Data Privacy Framework |
| Arcjet | Rate limiting, bot detection and disposable-email blocking | IP addresses, request metadata, email addresses (validation) | United States | EU Standard Contractual Clauses (SCCs) |
Hosting (Vercel) and backend (Appwrite Cloud) publish their own status pages: vercel-status.com and status.appwrite.online.
The check-in escalation cron is monitored with Sentry Cron Monitoring: a silently missed run pages us. The deadman's switch itself has a deadman's switch.
Errors are tracked in Sentry with PII scrubbing applied before anything leaves our servers.
Found a vulnerability? We want to hear about it before anyone else does. Email security@emberalis.com and give us reasonable time to fix the issue before public disclosure; we commit to acknowledging reports within 72 hours and will not pursue good-faith research. Machine-readable details live at /.well-known/security.txt.
We answer every security and privacy question, in detail. That is the whole point of this page.
Contact us